whats-best.ai

Business Instant Messaging · head-to-head

Element vs Mattermost

Element

UK / wider Europe

Panel rating

Sovereignty: 1 of 4 dimensions proven

Full evaluation →

Mattermost

Rest of world

Panel rating

Sovereignty: 1 of 4 dimensions proven

Full evaluation →

The written short answer is being updated after a re-evaluation. The scores below are current.

Read this comparison as one judge. Each weighs the same scores by what they care about.

The Works Council Advocate

Knows that a chat log is a record of who spoke to whom at what hour. Wants presence a person controls, no individual activity scoring anywhere, retention that deletes rather than hides, and analytics that can be switched off across the organisation.

Element

Mattermost

This judge's pick

Criterion by criterion

Channels, threads & search

Element

Real threads, reactions, attachments, polls and unlimited history are all evidenced, and federation reaches across organisations. But the evidence is entirely silent on search, mentions, edit history and pins — a works council that cannot find the decision made eighteen months ago is flying blind, and silence is information.

Mattermost

Channels and threads are real enough to have their own API endpoints and even a beta operation to move a thread to another channel, with guest accounts, file previews, and, on the Enterprise plan, shared channels and Matrix-protocol federation; edits and deletions are retained in the record by default, and search is documented at a three-million-post scale on Professional and beyond that on Enterprise. We found no public information on pinned or saved items, search filters by channel, person or date, or channel archiving and merging.

Encryption & access control

Element

End-to-end encryption is the default mode on an open, source-visible protocol, devices verify by QR code or emoji string, and the vendor states plainly that encrypted content is never accessed by its teams. Docked one point because admin-revocable session management and guest accounts with scoped visibility are not evidenced anywhere in the evidence.

Mattermost

Transport and at-rest mechanisms are documented concretely — TLS with AES-256 and 2048-bit RSA, disk-level encryption on infrastructure the customer runs, S3 with S3-managed keys, and cluster traffic encrypted with AES-256 — and the deployment guide says plainly that the database is not encrypted at the application layer so that search and compliance reporting keep working, which is the kind of honesty I want more of. Granular role-based access, AD/LDAP sync, SSO, guest accounts and zero-trust channel access are evidenced; we found no public information on end-to-end encryption of message content, device verification, or sessions an administrator can revoke.

Retention, discovery & co-determination

Element

Rules-based retention with a documented seven-day window before permanent deletion — deletion that deletes rather than hides — and an explicit statement that homeserver users are not profiled, which is exactly what I ask for. But legal hold, eDiscovery export, an administrative audit trail and user-controlled presence are all unevidenced; the 'auditing' on offer is an in-room record, not an admin log.

Mattermost

Compliance export runs in formats a lawyer already uses — Global Relay EML, Actiance XML, Proofpoint — tracking each message by ID through edits and deletions, with job status visible and every query and download action logged in an audit history explicitly to prevent unauthorised queries; that last part is the co-determination instinct done right. Data Retention Policy and Legal Hold are named at the Enterprise tier and self-hosted telemetry can be opted out; but the default retains everything including deletions rather than deleting, and we found no public information on presence a person can control or on activity analytics and whether they can be switched off organisation-wide.

Deployment & data custody

Element

Custody can genuinely be the customer's: an AGPL FOSS distribution of frontend and backend, self-hosting as a first-class deployment including air-gapped with no internet, official Helm charts, vendor-agnostic federation, and export positioned against lock-in. One point off because the community homeserver is declared not for production and the export format itself is undocumented.

Mattermost

Custody really can be the customer's: the same server installs via Kubernetes, Linux or containers, an air-gapped runbook with a bill of materials and registry mirroring is published, FIPS-compliant STIG-hardened images exist, and the customer stands up the database, file storage and TLS themselves — with Matrix-protocol federation and Slack-compatible webhooks giving paths in and past message history exportable via a command-line tool. The compliance export excludes Playbooks and Boards data, and we found no public information on a complete single-format export of an entire workspace.

Integrations & extensibility

Element

Named integrations exist — Jira, OpenProject, NeoBoard widgets — alongside SCIM, LDAP and OIDC identity plumbing. But the evidence evidences no documented REST API, no webhooks, no slash commands, no bot account model and no rate limits, so I cannot confirm this is buildable without a partner agreement.

Mattermost

A versioned REST API documented endpoint by endpoint with its permission requirements, incoming and outgoing webhooks available on every plan including the entry edition, Slack-compatible webhook payloads, interactive dialogs and Mattermost Blocks, plus admin-enforced channel locking for webhooks — a control I am glad to see. We found no public information on an app directory, SCIM provisioning, documented rate limits, or an event-subscription model with retries.

European sovereignty

Element

Deployments can sit in EU AWS regions and the privacy policy does publish a subprocessor list — but the controller and contracting entity are Element Creations Ltd in London under the UK ICO, and the chain includes Cloudflare, Twilio, Salesforce, Salesloft and Hubspot. The air-gapped self-hosted edition is what actually removes the question, and it should not have to.

Mattermost

The captured pages show a United States vendor relying on the EU–U.S. Data Privacy Framework and Standard Contractual Clauses, personal information transferred to the United States, Google Analytics on the sites, Azure and AWS named as cloud hosting for US-headquartered providers, and no published list of the subprocessors behind the vendor-managed cloud. The documented air-gapped, self-hosted path with telemetry opt-out is what removes the question in practice for a European deployment, but the contracting entity sits outside the EU and we found no public information on EU hosting or an EU entity.

Pricing transparency

Element

The community edition is genuinely free, but the Pro tier says 'Priced per seat/month' directly beside 'Talk to an expert', with unnamed 'price minimums' per additional server. No public number exists anywhere on the evidence, so no works council can compute the annual invoice from published pages.

Mattermost

The captured pricing page routes every named plan to a sales conversation — Professional to "Contact Sales", Enterprise to "Get Pricing", Enterprise Advanced to "Request Quote" — and we found no public per-user price for any tier anywhere in the captures. A limited-use free edition of Enterprise Advanced is offered for technical evaluation, but no buyer can compute an annual invoice from these pages.

Sovereignty, side by side

Dimension Element Mattermost
Legal entity Not determined Not determined
Ownership Not determined Not determined
Data residency Not determined Not determined
Subprocessors US CLOUD Act reach US CLOUD Act reach